ServiceNow AI Platform CVE-2026-6875: Unauthenticated RCE Already Exploited
The CVE-2026-6875 vulnerability in the ServiceNow AI Platform allows an unauthenticated attacker to execute remote code on self-hosted instances. Searchlight Cyber disclosed it on July 14, 2026, and ServiceNow released patches the same day, but observed attacks in the wild began a few days later. Defused Cyber and other observers reported active exploits, indicating that the flaw quickly moved from disclosure to real-world exploitation. The risk is high because it affects a platform used for sensitive business processes and because the lack of authentication greatly lowers the barrier for attackers. Organizations hosting ServiceNow on-prem or in exposed configurations must patch immediately and check logs and sessions for any anomalous activity.
Sources
- Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875 — Security Affairs
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution — The Hacker News


Leave a Reply